Cross-Site Scripting Vulnerability in Polarion ALM and WebClient
CVE-2021-44478

6.1MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 March 2022

Summary

A cross-site scripting vulnerability has been discovered in Polarion ALM and Polarion WebClient for SVN. This vulnerability arises from the inadequate handling of data sent to the web page via the SVN WebClient. Attackers could exploit it by crafting malicious links, which, when accessed by users with administrator privileges, may allow them to execute arbitrary code and extract sensitive information. This poses a significant security risk to users and organizations utilizing the affected versions of the products.

Affected Version(s)

Polarion ALM All versions < V21 R2 P2

Polarion WebClient for SVN All versions

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.